Audit of Civilian Human Resources Management System (HRMS(Civ)) application access rights . : D58-271/2015E-PDF

“The current HRMS(Civ) user access management framework is not sufficiently rigorous to ensure the integrity and confidentiality of HR data. There is a lack of key system accreditation requirements, limited documentation on the consistent use of the HR data, weak access controls, unclear roles and responsibilities, and the wide distribution of the HR data outside of the HRMS system. The Department is thus unable to ensure that the HR data has been safeguarded, used appropriately, and secured from unauthorized use. As a result, a privacy breach involving the personal data of current and former employees and CAF members may have occurred. Taken in its entirety, these factors create a risk to people's personal information, as well as to the reputation of the Department. Given the sensitive nature and pervasive use of personal information within the Department, stakeholders must be proactive and provide an enterprise approach to the assessment and management of this situation. Based on TBS policy requirements and guidelines, the Department should take expedient action to resolve the identified privacy and security issues and should ensure that the proper user access framework is in place going forward”--Conclusion, p. 15.

Lien permanent pour cette publication :
publications.gc.ca/pub?id=9.833070&sl=1

Renseignements sur la publication
Ministère/Organisme Canada. Department of National Defence. Chief Review Services.
Titre Audit of Civilian Human Resources Management System (HRMS(Civ)) application access rights .
Variante du titre Audit of HRMS(Civ) application access rights
Type de publication Monographie
Langue [Anglais]
Autres langues publiées [Français]
Format Électronique
Document électronique
Note(s) Issued also in French under title: Audit des droits d’accès à l’application du Système de gestion des ressources humaines civiles (SGRH(Civ)).
Cover title.
At head of title: Reviewed by ADM(RS) in accordance with the Access to Information Act. Information UNCLASSIFIED.
"December 2015."
Information sur la publication [Ottawa] : National Defence, [2016]
Description 33 p. in various pagings
Numéro de catalogue
  • D58-271/2015E-PDF
Numéro de catalogue du ministère 7050-33-9 (ADM(RS))
Descripteurs Human resources
Computer security
Audit
Demander des formats alternatifs
Pour demander une publication dans un format alternatif, remplissez le formulaire électronique des publications du gouvernement du Canada. Utilisez le champ du formulaire «question ou commentaire» pour spécifier la publication demandée.
Date de modification :